Tag Archives: geopolitics

Data Localization is the Answer. What Was the Question?

Last week I gave a talk at Chatham House for an event on ‘Is Data Localisation the Answer to Data Sovereignty? Location, Control and the Architecture of Trust’,  organised in collaboration with their Digital Ambassadors Forum. I really enjoyed the conversation and questions and had a number of people ask for slides and more details so have put together the following summary.


Four years ago I had the privilege of hosting digital transformation leaders from around the world at Rockefeller’s Bellagio conference centre. In the room we had senior officials from governments that represented at least 2 billion people. Much of our conversation focused on digital public infrastructure (then…a new topic) but at one point the conversation shifted to data and sovereignty. Most leaders in the room insisted that yes, data mattered and, obviously, data localization was the answer. Everyone, that is, except the Ukrainian in the room. We’ll come back to that.

If data localization is the solution… what problem is it solving? What is the nature of the “data sovereignty” we think is a threat? My experience is that data’s location says very little about sovereignty… and the reduction of local vs abroad on where data is stored both presupposes some fairly pre-digital notions of sovereignty and ignores a lot of options and tradeoffs that could befuddle a policy maker. If you’re too busy to read any of this post, this first slide sums up much of what I’m getting at. On one axis is a range of models for storing data. Some are “local,” others are not. On the other axis is a range of threats one should be thinking about when storing data (this list isn’t even exhaustive). The resulting matrix (which would be unique for any country or company) tries to lay out the real tradeoffs between storage models and risk types. But more than anything else it suggests localization is not a magic cure-all for one’s policy or economic woes.

I think sovereignty (or as I prefer, agency) is best achieved via adopting multiple models to provide coverage against a range of threats. This also has tradeoffs, and, to be most effective suggests governments should be trying to shape the cloud market into being more interoperable. This argument – which I refer to as a “commoditized stack” – offers a more promising path to agency than anything currently on the table.

There is Both New Infrastructure and a Genuine Problem

First, some context. Any conversation about data, data localization and/or digital sovereignty has to contend with how and where data is stored. This quickly gets you to a topic I’m deeply interested in: the cloud. I recently presented to Europe’s finance ministers (the memo I wrote for them is published on the Eurogroup’s website) and I first sought to impress on them that “the cloud” is 21st-century infrastructure in exactly the way water systems, railways, electricity and telecoms were essential infrastructures in previous centuries.

The cloud – which at a minimum is the provisioning of storage and compute at scale – is now critical to any modern economy. It is a core input into services ranging from food delivery to government benefits to banking. Happily, most people get this, and it is a reason why concern over who controls data has become so important.

Whose Data are we Talking About?

There’s a second question hiding inside the “data localization” question. When a government says “our data must be localized,” which data does it mean? Its own — the tax records, health files and registries it holds in trust for citizens? Or the data generated by the entire economy — every bank, hospital, startup and grocery chain?

These are radically different problems. The first is, in many ways, a government procurement question. This is in part because states carry a special custodial duty. Citizens cannot opt out of giving the state their data. But it is also a function of the fact that states are expected to be actors of last resort, capable of functioning under even the most brutal circumstances – such as a state of war.

The second is industrial policy. Requiring the whole economy to localize means repricing compute and storage for every firm in the country. Most localization debates slide between “the government’s data” and “the nation’s data” without noticing they have changed the subject. For this piece, let’s assume we are just talking about government data, but you can easily expand this to the whole economy and see how the implications and tradeoffs become more daunting.

What is the Threat Model?

To return to our title, if data localization is the solution, what is the problem? Here policy makers would benefit from a little threat modeling, to understand what the threats (and potentially opportunities) data localization is seeking to answer.

At present there is a threat that many policy makers have in mind. In most European and OECD countries (and beyond), many people, when pressed, land on the same answer: lawful access (or unlawful access, depending on your point of view). Specifically, they are worried about the CLOUD Act, the 2018 US law that lets American authorities compel US providers (like AWS, Azure or Google Cloud) to hand over data stored on servers they manage, regardless of where they are located around the world. Somewhat related, people also worry about a denial of access, whereby, via legal means, a government might be denied access to its own data.

I too find the CLOUD Act deeply, deeply problematic, and an excellent reason why one should think carefully about becoming reliant on US (or Chinese) cloud providers. But it isn’t the only threat to a government’s data. Here, for example, is a fuller list:

Lawful (or unlawful) access remains a threat. And there are others:

  • Access denial: not someone reading your data, but someone simply turning the servers off, or severing connectivity to them, because they can.
  • Cyber attack: an actor stealing or ransomwaring your data.
  • Data colonialism: an actor exporting data outside your jurisdiction to be exploited by foreign firm(s).
  • Lack of capacity: an inability to use or protect your own data.
  • Competitiveness: when storing, managing and accessing your data is simply more expensive than in other jurisdictions, leaving you at a competitive disadvantage.
  • Act of God: Your ability to access your data (particularly if stored in a single location or region) is at risk from a natural disaster.

Any one of these can compromise data integrity or security – which would suggest it is core to discussions about “data sovereignty” – but almost none of these figure in the political discourse. Everyone focuses on the lawful access and access denial problem. (To be fair, I find most engineers and business people are thinking about all these threats; it’s mostly policy people zeroing in on the first two.) But if you start to think about various possible threats, solutions become trickier as each threat points in a different direction.

Where does data actually live?

Once you’ve wrapped your head around the numerous ways the universe might conspire to destroy your data, you have to reconcile that with the options you have to store your data. There are several and one can somewhat imperfectly align them along an axis of “foreign controlled” to “locally controlled.”

At one end you have your classic hyperscaler model, a US firm offering almost limitless storage, with high redundancy (as well as a range of other platform services) all subject to the CLOUD Act, with your data primarily stored in a data centre in Virginia. At the other end, a government-owned data centre you nominally control entirely (we could debate the provenance of the technology inside it, but set that aside). In between sit a range of actors we rarely bother to distinguish: a firm headquartered in your country that hosts your data in a datacentre located abroad; a hyperscaler’s local data centre on your soil (but still subject to the CLOUD Act!); a domestic joint venture running on licensed foreign technology; a domestic firm hosting domestically. Very different rules apply to each.

In addition, what is foreign controlled and locally controlled has little alignment with data localization. Indeed the localization debate flattens them into “local good, foreign bad” which, depending on your threat model, may have profound, and not necessarily positive implications for your data’s security or sovereignty.

To make this more obvious you can run the aforementioned threats against this spectrum of options. This is where it gets uncomfortable.

Lawful access: localization doesn’t help

Start with the threat everyone cares about. The CLOUD Act applies to data sitting in Ireland, or the UK, or Montreal on an American hyperscaler exactly as much as it applies to data sitting in Virginia. The Act follows the company, not the geography. Moving your data into a hyperscaler’s local data centre — the single most popular “sovereignty” measure on offer (and one whole procurement frameworks are built around!) — does not address this threat.

This is one reason why governments are being persuaded to invest in their own “local” or “national” clouds. Sovereignty is derived from ownership (which, as we’ve seen, it may not be) and comes with its own tradeoffs…

What actually helps against lawful access is holding your own encryption keys, or using a provider genuinely outside the requesting state’s jurisdiction — and each of those brings its own trade-offs from elsewhere on the list.

Cyber attack: you might be safer on the hyperscaler

Against a serious state-backed attacker, where do you want your data? The honest answer is awkward: probably on the platform with the largest, best-resourced defensive security team on earth. If you’re a middle power government, or a large, successful private company, do you trust your state agencies to out-defend firms whose security teams and budgets dwarf your own? If your “A” team is protecting national secrets, who’s left to protect more mundane things like social benefits or the DMV? If you’re concerned about attacks from North Korea, Russia or China — states with sophisticated capabilities – this analysis becomes even more awkward. Localizing your data onto weaker domestic infrastructure can make this threat worse.

Access denial: ownership beats location — sometimes

Access denial is the threat I think deserves far more attention than it gets. Forget reading your data; someone with control over your infrastructure can simply deny you access to it. Maybe via legal process, or… not. They could just turn the power off or sever a key network cable.

Here the spectrum behaves differently. Physical denial is possible for anything hosted outside your borders — including by a domestically-owned firm operating internationally. Legal denial can reach even a foreign-owned entity that happens to sit on your soil: if the parent company is ordered to stop serving you, the local data centre goes dark just the same. Only the bottom of the spectrum — genuinely domestic operations — offers much protection.

Localization can help here… with caveats. A domestic operation still depends on hardware, software and services that are not indigenous to your country. You may have traded a low risk of someone flipping the off-switch for an elevated cyber risk and the slow grind of a degraded service. But of all the threats on this list, access denial is the one localization most clearly addresses.

Attack and act of god: the safest place may not be your country

Remember the Ukrainian in the room at Bellagio, the one person least sold on localization? They were the ones presenting. It was a talk I still think about: photo after photo of bombed-out Ukrainian data centres. When your threat model includes missiles, “keep the data at home” reads very differently. Data localization isn’t necessarily the best defence against hostile acts. Ukraine has become a significant adopter of US hyperscalers. They are not alone. Estonia drew this lesson a decade earlier and implemented its data embassies, placing core data abroad on purpose to ensure continuity of service in the event of a hostile kinetic attack.

Data localization can also carry risks and tradeoffs. Last September, South Korea’s National Information Resources Service — the government’s own data centre in Daejeon — experienced a fire. Six hundred and forty-seven government services went down. Ninety-six systems were destroyed outright, including G-Drive, the government’s internal file store: roughly 858 terabytes of working documents, gone. There was… no backup. Last time I searched, it was still unrecoverable. This wasn’t an attack. It was infrastructure, in one place, and that one place burned.

The hard reality is, depending on your threat model, the safest place for your data may not be in your country. My home of Canada has the luxury of being enormous — an act of God is unlikely to take out data centres in Vancouver and Montreal simultaneously (if it does, I suspect we collectively, as a planet, have bigger problems). But many countries don’t have that luxury. If you’re Belgium or an island nation, I’m not sure you do. As mentioned above, Estonians have decided, explicitly, that they don’t. An Estonian “data embassy” in Luxembourg (and possibly elsewhere) stores sovereign Estonian data abroad, precisely because it’s safest there.

Data colonization: it’s about who collects, not where it sits

One more, because it exposes the frame’s deepest flaw. If your worry is the extraction of your data’s economic value — data colonialism, industrial loss — then where the data is stored is only part of the issue. Equally important is who collects it. A foreign application harvesting your citizens’ data will do so regardless of which data centre it rents. Does a domestic company that collects the data, then chooses to store it abroad, raise bigger questions than a foreign company storing your data locally?

Every Choice is a Trade-Off

To really drive this home I created an illustrative matrix of these trade-offs. The ratings would likely differ from country to country, but it gives one a sense of the terrain. There is no row that is all green. There never will be. And that is my point. Data localization is a solution to a very specific threat model… an important one, but a specific one. And the notion that you should spend billions or more to create a national champion to solve for that problem is… a trade-off in its own right that, even executed well, may carry significant risks and downsides.

So the first conclusion of the talk: data localization is not a strategy. It is a tactic that addresses some threats, may sometimes be effective for the headline threat, and actively worsens others. If someone is leading with localization, the serious response is: against which threat? Until that question has an answer, it’s hard to balance risk and reward, costs and options.

Moving from Sovereignty to Optionality

So what would a more successful strategy for achieving “sovereignty” look like? First and foremost, it means not starting with a solution but with a threat model — and being honest about the tradeoffs in addressing each threat. As we’ve just seen, that exercise rarely lands on a single answer.

I think it also lies in creating optionality, both domestically and internationally. This is what I’ve argued for in The Path to a Sovereign Tech Stack is Via a Commodified Tech Stack. The core thesis being that standardizing storage at the cloud level, and then, ideally, platform-as-a-service functions, would bring portability, competition and federative options to the cloud layer – including, critically, around data storage.

Focusing on choice and interoperability creates a range of more interesting options than focusing on “sovereignty” since, as I previously mentioned, that conjures up unhelpful notions that conflate territoriality and ownership with control and security. Mike Bracken and I first suggested agency was a more helpful term in our Lisbon Council piece on Europe’s Digital Strategy. Mike’s gone on to write some additional good thoughts, but here is one of my favourite parts of that original piece:

Which brings us to a deeper concern: the framing of digital sovereignty itself.

We understand the instinct. In a world where digital infrastructure is often foreign-owned and opaque, wanting more control is natural. But sovereignty, if defined as owning every layer of a technological stack, can quickly become counterproductive. It leads to balkanized systems, limited interoperability and a retrenchment from global cooperation. The incentives for creative development disappear. Competition and innovation subside.

Instead, we should be aiming for digital resilience and interoperability.

Summary Advice

If you’ve read this far, here is the version to carry into your next meeting.

Data localization is an answer waiting for a question. Before adopting it, name your threat model. If the threat is the CLOUD Act, localization does not help you — the law follows the company, not the geography. If the threat is a state-backed cyber attack, localization may hurt you. If the threat is access denial, it helps — read the fine print on ownership. If the threat is fire, flood or missiles, the safest place for your data may be another country entirely; ask Estonia, or ask South Korea, which kept its data sovereign, domestic, in one building, and lost 858 terabytes of it in an afternoon.

If you carry only three questions out of this post, make them these.

Whose data? A rule that is prudent stewardship for a tax agency becomes an economy-wide tax when applied to every firm in the country.

Against which threat? Localization genuinely helps with some threats, does little for the headline one, and makes others worse. Name the threat, and the right storage model usually names itself.

Can you leave? Sovereignty that depends on any single provider’s goodwill — foreign or domestic — isn’t sovereignty. The durable kind comes from being able to move. That’s the commoditized stack argument, and it’s the subject of my next post.


The Chatham House conversation was held under a mix of rules; nothing here draws on anything said in the room — this is the argument I brought in. Related: Parting Clouds (with Curtis McCord, for the Canadian Anti-Monopoly Project), The Path to a Sovereign Tech Stack is via a Commoditized Tech Stack (Tech Policy Press), and NATO’s Digital Back End Could Fall Apart Without Change (Foreign Policy). If you’re working on any of this elsewhere in the world, I’d like to compare notes.

left wing tonic for Michael Byers

Recently I’ve been reading more and more of Policy Options. I’m not a reading every issue (although I’m not trying to) but I am enjoying much of what I do get through.

Going way back to the February issue there was an article by Robin Sears entitled “Canada in North America: From Political Sovereignty to Economic Integration.” The piece was a hard assessment about the limits of Canadian sovereignty and economic independence in light of our geographical position next to the United States. He notes that our position is one where we must work with our American cousins and try to gain as much influence as possible – a bold statement these days – but one that remains true. Perhaps no more so today. When things are at their worst (and I’ll admit, they are) that’s precisely when we need a map for a better path. As Sears points out…:

Imagine the vision, the courage and imagination that it took in the harsh winter of European famine of 1947-48 for two powerless French statesmen to sit in a Paris café and begin to plan for a united Europe! …They reflected grimly on “the success of the victorious Allied powers” in Europe.

The continent was being savaged by Soviet armies in the east and staggered under starvation in the west. The only European unity any rational person could foresee was a shared visceral hatred of Germany and everything it had stood for. The miracle that was the Marshall Plan was still in the future. Germany was a decade away from its economic leap forward. England, torn by its loss of empire, with its special relationship with the United States and its eternal ambivalence about Europe, was unreliable.

The simple fact is, we are stuck on this north american rock with the a powerful neighbor who knows little about us, and cares less and less every day. The only thing that will be worse is when they suddenly do care about us – like our border after 9/11. Sears’ is at pains to find ways to foster political structures to promote cooperation between Canada and the United States and he’s right. We need them. Those who wish to die at the altar of sovereignty, preserving it absolutely at no matter what cost, will find that they have significantly less influence, not only abroad, but at home as well. Worse, sovereignty is usually not what they care about. In perhaps the pieces most biting line, Sears points out:

“Canadian nationalists trying to ring-fence our sovereignty are engaged in an especially ironic struggle, given their citizenship in the nation that invented the modern, more supple form of sovereignty: federalism. Those who are most determined to draw deeper lines in the ongoing crusade against American encroachment on our national sovereignty are often the strongest advocates of Canada’s leadership in the development of global governance through multilateral institutions. The contradiction reveals less about their convictions about sovereignty than about their plain vanilla anti-Americanism.”

Ouch.

The piece is interesting and worth reading on its own merits. But what makes it still more compelling is its author. So who is this man? Excellent question. First, despite the article’s bent, analysis and conclusion, he’s not a Conservative. No, for the uninitiated (like me) Robin Sears was the national campaign director of the NDP during the Broadbent years and served as Bob Rae’s chief of staff when he was premier. He was also Deputy Secretary General of the Socialist International. For those on the left whose only prescription to our geographic conundrum is to seal the border and throw away the key (a proposition that would see no end of pain for the Canadian economy) it is interesting to find those, on the same side of the spectrum, who disagree. I hope we see more of them… frankly the debate needs their perspective.

Firefox 3 pledge map vs. the Pentagon’s new map

What are the geopolitics of open source? To find out I thought it would be interested to see how Thomas Barnett’s map meshed with the Spread Mozilla Firefox 3 download pledge map.

Some brief background for those not familiar with “The Pentagon’s New Map.” It is a map that sits at the heart of a book of the same title written a few years ago by Barnett. It is a compelling take on what America’s grand strategy should be for the 21st century and how it is, and more importantly isn’t, ready to execute on it. Better yet, it is engaging, thought provoking, interesting, and written so anyone can read and understand it.

The core of the book’s thesis (remixed from Wikipedia and very high level) is as follows:

  1. International systems of rules reduce the likelihood of violent conflict (e.g., the WTO Dispute Settlement Understanding)
  2. The world is divided between the Functioning Core and the Non-Integrated Gap.
    Function Core = economic interdependence, incented to abide by rules
    Non-Integrated Gap = unstable leadership and absence of international trade, weaker incentives
  3. Integration of the Gap into the global economy provides opportunities for individuals to improve their lives, presenting a desirable alternative to violence and terrorism
  4. US grand strategy for the 21st century… help countries migrate from the Non-Integrated Gap into the Functioning Core

According to Barnett’s thesis, countries in the Non-integrated Gap, because they are less connected, should probably have fewer computer users, fewer people downloading software and fewer people participating in Open-Source projects. Mashing up his map with the Firefox pledge map might give us some a clue to how well open-source conforms to his thesis.

(Note, I’ve remixed Barnett’s map to make it is easier to read on a computer with the Function Core countries in green and the Non-Integrated Gap countries in red . You can find the original map here.

PNM remixed

Below is the spread Firefox pledge map, which tracks how many people around the world have pledged to download Firefox on its release day (June 17th). I’ve overlaid the Non-Integrated Gap/Function Core border over it.

firefox PNM mash up

Some comments/thoughts:

  • Interesting correlation between low pledge totals and Non-Integrated Gap countries
  • All but two Non-Integrated Gap countries (Colombia & Turkey) have 10,000 download pledges or fewer. (I also think it is interesting that Barnett doesn’t include Turkey in the Functioning Core…)
  • Most countries within the Functioning Core have 10,000 pledges or greater (South Africa, Nordic Countries and the Baltic States are notable exceptions)
  • Non-Integrated Gap countries with the most pledges are Iran, Turkey, Venezuela, Peru, and Indonesia – interesting list. Seems to suggest that many of the countries the US tries to isolate are actually the most connected.
  • According to my Mozilla friends Poland (yes, Poland) was the first to hit the 100K pledge mark. Many new Core countries are adopting Open Source en mass to avoid paying for expensive Microsoft software. Open source may be offering them a cheap way to increase connectivity and integrate with the core faster, and on their terms. Fantastic outcome.
  • This map DOES NOT account for population variation – would be fascinating to see a map based on per capita pledges (I’ve contacted my friends at Mozilla and they’ve passed the raw data along to me so I will follow up with that analysis ASAP)
  • I will try to update the map with the final data on download day (June 17th) when all the pledges have been tallied
  • Note: Firefox pledge map copied on June 15th, 2008, 8:30 pm PST

Lots more thoughts and analysis to be done on this. I hope to blog more on this shortly. If Barnett responds in any way I promise to update – would love to hear his thoughts/reflections on this.

(One final aside, if you get the chance to see Barnett present, do so. He’s up there with Lessig in his delivery. I remember seeing him at a conference. He went long by 10 minutes. The US ambassador to Canada was in the next room waiting to give the next presentation but if any of the organizers had tried to intervene and hurry Barnett up, they would have been lynched. FYI, You can see his TED talk here.)

Foreign Policy in Asia

This story is an interesting update on the growing links between the United States and India.

The integration of India into the broad alliance of Western Democracies will probably be the most important geopolitical challenge and opportunity of the first half of the 21st century.

Conservatives (or for IR geeks, Neorealists) will like it because it will help contain China. Liberals will like it because it will both strengthen a democratic anchor in the heart of Asia and create a powerful ally whose values and ideals are broadly aligned with our own.

India is bankable because it is increasingly capitalistic and democratic, has an independent judiciary, and its demographics are slowly stabilizing. This puts it in sharp relief against China which is increasingly capitalistic and authoritarian, possesses a weak rule of law, and has highly unstable demographics (the one-child policy is causing both a gender imbalance and creating the longer term crisis of a suddenly contracting population). In short, China has the short term potential of being quite powerful, but over the long term, could become a source of instability. India, over the short term runs the risk of being impotent, but over the longer term could become a source of power and stability. Hence, the western economies are happy to trade with China, but the relationship ends there. With India, they not only want to trade but also explore the possibilities of partnership.

So where is Canada in all this?

Unclear. I’ve seen no evidence that we are making ourselves indispensable to the key players in this new alliance. And, as our experience in NATO has taught us, it is always good to get in on the ground floor. Alas, you have to have a reason to get in the door. It’s not clear we have one. And that is very, very, bad news.

Afghanistan – Exploding the mission

The Asia Times Online has reported that the United States and its NATO allies have been granted permission to hunt for the Taliban inside Pakistan.

This is a dramatic change in the mission.

The upside is significant. Extending the use of force into Pakistan denies the Taliban a safe haven from which to prepare and launch attacks in Afghanistan.

The risks however, are equally significant. This is a major escalation of the war. Indeed, it is, in many ways, precisely what Al-Qaeda has always wanted – an expansion of the conflict into a broader war, one that brings to rise the thorny situation of having an (at best) semi-legitimate secular Pakistani government coordinate attacks against its own citizens in conjunction with US forces.

Moreover, the Afghan conflict has always served as an outlet for Pakistani extremists, a method of preventing civil war by focusing their attention abroad. This agreement could bring those chickens home to roost – causing a civil war between secular and fundamentalist Pakistanis – all with American involvement.

If it goes well it will be a major blow against extremism. If it goes poorly, the geopolitical consequences will make Bush’s disastrous adventure in Iraq look like a historical footnote in comparison.

These stakes are big.

(good to see Canadian newspapers have so far ignored this important development)